Privacy Policy
Version 2026-08-28, which is the date this policy took effect.
1. Who is responsible
IslandPlay is a booking service operated from Trinidad and Tobago, and it decides how the information described here is used. Write to [email protected] about anything on this page.
A business you book with also sees some of your information, described in section 5. What they do with it beyond running your booking is their responsibility, under their own privacy practices.
2. What we collect
All of it comes from you or from what you do in the app. We do not buy data about you and we do not combine what you give us with data from anywhere else.
Your account
Your email address and a password, which is stored only as a hash and cannot be read back. Optionally a first and last name, a display name, a phone number, a date of birth and a home region. A phone number is not required and is never used to identify you — two accounts may hold the same one.
Children you book for
A name and a date of birth. Nothing else. There is no field anywhere for a medical note, an allergy, a school or a photograph, and that is a deliberate decision rather than a gap: a system that holds children's medical information has to be built to a standard this one does not claim.
Bookings and what you buy
What you booked, where, when, for how much, whether you turned up, and anything you added to it — equipment hire, a programme place, a pass. Cancellations, including who cancelled and the reason given.
Payments
Never your card number. Card details are entered on our payment processor's page and never reach us. What we hold is the amount, the currency, the status, the processor's reference for the transaction, and — if you saved a card — a token from the processor plus the brand, the last four digits and the expiry month and year.
Waivers you accept
Which document, which version, when, who accepted it and on whose behalf — and, because a waiver is a record of consent that may have to be relied on, your IP address and browser user-agent string at the moment you accepted it.
Signing in
Each active sign-in stores a hashed session token, the IP address and the user-agent it was created from, and when it was last used, so you can see and end sessions. Failed sign-in attempts are recorded briefly against the address and the account, to rate-limit password guessing.
Messages we send you
Confirmations, reminders, cancellation notices and receipts, with the address they went to and whether they were sent. Your notification preferences. Email is the only channel — the app sends no SMS and no push notifications.
If you enquire on the marketing site
The name, business, email, phone, note and IP address you submit in the enquiry form, so we can reply.
If you run a business on IslandPlay
Your venues and their addresses, opening hours, prices, branding and photographs; your staff's accounts and their roles; your bank details for payouts — account name, bank, branch and account number; and an audit record of who changed what, described in section 5.
3. What we do not collect
These are worth stating plainly, because most services do the opposite.
- No cookies. Not for analytics, not for advertising, and not for signing in. IslandPlay sets none at all.
- No analytics. There is no analytics SDK in the app or on this site.
- No advertising or tracking. No ad network, no pixel, no third-party tag.
- No crash or session recording. Nothing watches what you do on screen.
- No location tracking. Venue addresses are the venue's; your device's location is never requested.
- No contacts, photos, microphone or camera. The app asks for none of them.
4. Why we hold it
- To run your bookings
- Taking the booking, telling the venue, letting you in, taking payment, sending a receipt, handling a cancellation or a refund.
- Because we have to
- Financial records of money taken and paid out, and evidence of consent where a waiver was signed. These are kept whatever else happens to your account.
- To keep the service safe
- Rate-limiting sign-ins, investigating a disputed payment, and the audit record of who changed what inside a business.
- To tell you things about your bookings
- Confirmations, reminders and cancellations. These are part of the service rather than marketing; we do not send you promotional email unless you have asked for it.
5. Who can see it
A business sees the customers who booked with it, and only those. For a booking at their venue they see your name, your email, your phone number if you gave one, what you booked, what you paid and whether you turned up. They do not see anything about your bookings anywhere else on IslandPlay, and they cannot see another business's customers.
This is enforced in the database, not in the app. Every table carries row-level security rules, so a query that asked for another business's rows would return nothing at all rather than relying on a screen to filter them out. A coach sees the sessions they are coaching. A member of venue staff sees their own venue.
What our own staff can see. Platform administrators can see across businesses, because reconciling payments and sending refunds by hand cannot be done otherwise. Actions taken inside a business are written to an audit record — who did it, what changed, and when — which applies to our staff as much as to a venue's.
6. Who else receives it
The card processor — WiPay
Payments are handled by WiPay Caribbean. What is sent to them when you pay is, exactly: our merchant account number, the country code, the currency, the environment, the fee structure, the payment method, an opaque order reference, the word "IslandPlay", a return address, and the amount.
Your name, email address and phone number are not among them. The order reference is a random identifier that means nothing outside our system. Anything you type on their page — your card details — is theirs and governed by their privacy policy, not ours.
Email delivery
Our email delivery provider receives the address a message is going to and the message itself, in order to deliver it. That is all it is sent.
File storage
Venue logos and photographs are held by our file storage provider. This holds business branding only — no customer uploads anything and there are no profile photographs.
Map tiles
The map for placing a venue's pin, which appears only in the business portal, loads its tiles from OpenStreetMap. Your browser's IP address is visible to OpenStreetMap when it does, as it would be for any image loaded from another site. Customers never load it.
Hosting
The application and its database run at Render (render.com), in the United States, which necessarily has technical access to the servers holding the data — see section 8.
Nobody else
We do not sell your information and we do not share it for anybody's marketing. We would disclose it if the law required it, or to establish or defend a legal claim.
7. What is stored on your device
No cookies, as above. What the app does keep, in your browser's local storage or the app's own storage, is:
-
booking.accessTokenandbooking.refreshToken— the tokens that keep you signed in. -
booking.tenant— which venue's page you are on. -
booking.actingOperator— in the business portal only, which business is currently selected. -
nav.state.<your user id>— which screen you were last on, so the app reopens where you left it.
All of it is removed when you sign out. None of it is sent anywhere except back to us with your requests.
8. Where it is kept
Your information is stored in the United States, on servers run by Render, our hosting provider. This means it is held outside Trinidad and Tobago, and using IslandPlay involves that transfer.
We chose this for the boring, honest reason: no provider we could find in Trinidad and Tobago offers managed databases with automatic backups and point-in-time recovery, and losing your bookings to a failed disk is the worse outcome. Access to the data is ours; Render has technical access to the servers it operates, under its own privacy commitments.
Two things reach systems that are not ours, and only these. Card details are entered on our payment processor's own page and never touch our servers — what we send them carries no name, email or phone, only an amount and an opaque reference (section 6). And an email we send you passes through our mail provider in order to be delivered, which is what delivering an email is.
Where those two companies hold what they receive is governed by their own privacy policies rather than this one. Both are named in section 6.
9. How long we keep it
Removed automatically
- Failed sign-in attempts — after one day.
- Password reset links — one day after they expire.
- One-time codes — one day after they expire.
- Abandoned checkouts and expired slot holds — swept regularly.
Kept deliberately, and why
- Financial records — every payment, refund, payout and ledger entry. These are the accounts. They are not deleted on request, and they are kept for at least seven years.
- Waiver acceptances — including the IP address and user-agent recorded with them. A record of consent that is deleted is not evidence of anything.
- The audit record — who changed what inside a business.
- Bookings — the venue's record of what it sold and to whom.
The honest part
Most other tables have no automatic retention window at all. Bookings, notifications, sessions, audit entries and the ledger are kept indefinitely today, because nothing deletes them. That is the current state rather than a policy.
What we intend, and are saying here so it can be held against us: a booking and its financial record are kept for seven years, as above. A notification is kept for one year — long enough to answer "did you send it". An ended session is kept for 90 days, because it is a security record. The audit log and waiver acceptances are kept as long as the business exists, for the reasons already given. None of that is automated yet; today it is a commitment rather than a job that runs.
10. Deleting your account
You can delete your account from the app. Doing so, immediately:
- Removes your email address, phone number, first and last name, display name, date of birth and home region from your account record.
- Removes your password.
- Ends every session, everywhere, so you are signed out on all devices.
- Marks the account anonymised, after which it cannot be signed in to.
What stays. The bookings themselves, the financial entries behind them, waiver acceptances and audit records remain, no longer attached to a name. A venue can still see that a session was sold and played; it can no longer see who by. We cannot remove the financial record without falsifying the accounts, and we do not remove a waiver acceptance because it is evidence.
Deleting your account does not automatically delete a child you added. Ask us if you want those removed too.
11. Your rights
Ask us and we will tell you what we hold about you and give you a copy. Ask us and we will correct anything wrong — most of it you can correct yourself in the app. You can delete your account as described above, and you can ask us to stop sending anything that is not part of a booking.
Trinidad and Tobago's Data Protection Act 2011 is only partly in force — the general data-protection duties it sets out have not all been proclaimed, so how much of it binds us today is genuinely unsettled rather than something we are being coy about. We honour the requests above regardless, and will not wait for proclamation to be told to.
We answer requests within 30 days.
12. Children
A child does not hold an account. An adult adds them to their own account as a dependant, giving a name and a date of birth, and is responsible for them. Nothing else about a child is stored, and a child cannot sign in, be emailed, or be contacted through IslandPlay.
A date of birth is held because some programmes have age limits and it is the only way to check one.
13. Security
- Everything travels over an encrypted connection.
- Passwords are stored as a slow one-way hash with a per-account salt. Nobody, including us, can read your password.
- Session tokens are stored hashed. A stolen copy of the database does not yield a working session.
- Access between businesses is enforced by the database itself, so a bug in a screen cannot leak another business's rows.
- Card numbers are never in our system to be exposed.
No system is perfectly secure. If something happens that affects you, we will tell you.
14. Changes
We will update this page when what we do changes, and the version and date at the top will say so. For a change that materially affects you we will tell you by email.
15. Contact
For anything in this policy, including a request to see or delete what we hold:
The same address as everything else. One inbox, read by the people who run the service.